What is GovRAMP?
GovRAMP is the security authorization program for cloud services sold to US state and local governments and educational institutions. StateRAMP announced in February 2025 that it now operates as GovRAMP; StateRAMP remains the legal name. The program verifies cloud providers against NIST 800-53 based security requirements with independent assessment and continuous-monitoring obligations, so participating governments can rely on a shared authorization instead of running vendor-by-vendor security reviews.
The longer answer.
GovRAMP applies the model FedRAMP established for federal procurement to the state, local, and education market: a common NIST 800-53 based baseline, independent assessment, and a central program office. A provider demonstrates its security posture once and reuses that standing across participating governments, which is why the program functions as a market-access gate for SLED cloud contracts.
Because GovRAMP is built on NIST 800-53, the configuration and monitoring evidence overlaps heavily with FedRAMP and TX-RAMP preparation. Continuous CIS benchmark scanning mapped to NIST 800-53, as CISGuard performs, produces the recurring hardened-configuration evidence the continuous-monitoring phase expects.
More questions on Regions?
Our compliance engineers can show you exactly how CISGuard handles Regions in a briefing scoped to your environment.